CVE Vulnerabilities

CVE-2015-7455

Published: Feb 29, 2016 | Modified: Apr 12, 2025
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.

Affected Software

NameVendorStart VersionEnd Version
Websphere_portalIbm7.0.0.0 (including)7.0.0.0 (including)
Websphere_portalIbm7.0.0.1 (including)7.0.0.1 (including)
Websphere_portalIbm7.0.0.2 (including)7.0.0.2 (including)
Websphere_portalIbm8.0.0.0 (including)8.0.0.0 (including)
Websphere_portalIbm8.0.0.1 (including)8.0.0.1 (including)
Websphere_portalIbm8.5.0.0 (including)8.5.0.0 (including)

References